Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques

Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques

First seen 21 Aug 2026, 00:51 UTC Feeds.FeedburnerTheregistercloud.google.comGbhackersBitdefender+3 75.5

Article Content

Browse articles
ThreatCluster

Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These groups exploit legitimate authentication workflows, such as OAuth and app password phishing, to compromise accounts. UNC6293 impersonates U.S. State Department officials, while UNC7005 and UNC5976 employ various social engineering tactics, including fake invitations and device linking. The attacks are highly selective, often targeting fewer than 100 individuals at a time, but they pose significant risks due to their sophisticated methods. GTIG has observed these operations since at least 2025, with ongoing adaptations to their phishing techniques. The current status indicates a persistent threat as these clusters continue to evolve their tactics.

Key Points: • Three Russian cyber espionage clusters are actively targeting sensitive sectors in the U.S. and Europe. • Attack methods include OAuth abuse and app password phishing, making detection challenging. • The operations are highly selective, often involving fewer than 100 targets per campaign.

Timeline

2025-06-01
UNC6293 phishing campaign reported
GTIG reported UNC6293's app password phishing targeting individuals critical of Russia, impersonating State Department officials.
cloud.google.com
2025-10-01
Continued UNC6293 operations observed
GTIG noted UNC6293's ongoing phishing attempts using similar tactics as previously reported, including impersonation of State Department officials.
cloud.google.com
2026-06-01
UNC7005 identified
GTIG first identified UNC7005, linked to APT29, targeting academia and diplomatic personnel with OAuth phishing.
Technadu
2026-08-01
UNC5976 activity reported
GTIG reported UNC5976's use of cloud infrastructure for token theft and deployment of malware against Ukrainian entities.
Technadu
2026-08-21
Current operations detailed
GTIG released a report detailing ongoing phishing campaigns by UNC6293, UNC7005, and UNC5976, emphasizing their evolving tactics.
cloud.google.com